Conformance report

VerdictCONFORMANT
SpecificationTEA OpenAPI 0.4.0
Spec sourcehttps://cyclonedx.github.io/transparency-exchange-api/spec/openapi.yaml
Targethttps://www.vulnetix.com/tea/public/v1
Catalogueopen-source projects, from their published releases
CredentialApiKey credential against a deployed server
Generated2026-08-01T04:28:26Z
Request concurrency32

Result

MetricValue
Operations declared by the specification23
Operations exercised23
Test cases160
Passed160
Failed0
Responses schema-validated85
Responses conforming to schema85

Performance

Cold start: 367 ms. That is the first request against a tenant whose object index is not yet built, which is one aggregate query over the tenant’s scan history. Every subsequent request inside the index’s lifetime serves from memory, which is what the steady-state figures below measure.

Each row replays one request shape 100 times at 32 in flight. Every response was schema-validated; validation runs after the timer stops, so it does not inflate the measurement.

RequestRequestsFailuresp50p95p99maxreq/sbody
list products100098.54 ms118.99 ms131.11 ms139.76 ms3006.1 kB
list product releases (full page)1000759.06 ms1028.06 ms1058.59 ms1058.65 ms3960.2 kB
list component releases (full page, descending)1000555.28 ms911.87 ms1072.48 ms1697.53 ms4951.4 kB
read one product100023.41 ms115.25 ms133.34 ms134.49 ms607236 B
read one product release100039.59 ms86.20 ms88.09 ms88.29 ms655637 B
releases of one product100037.73 ms57.01 ms61.11 ms62.98 ms7033.0 kB
component release with latest collection100036.77 ms47.54 ms48.68 ms49.43 ms7971.8 kB
latest collection100042.27 ms66.69 ms68.17 ms68.57 ms701536 B
resolve a TEI100023.89 ms28.87 ms29.94 ms30.23 ms1081143 B
artifact metadata100027.39 ms36.13 ms36.72 ms36.78 ms947291 B

Conformance-phase latency

The distribution across all 160 conformance cases, one request each including the error paths, measured client-side to the last byte of the response body, 32 in flight.

Requestsminp50p95p99maxmean
16021.70 ms48.80 ms212.85 ms257.85 ms289.88 ms82.86 ms

Efficacy

Conformance proves the responses are well-formed. It cannot prove they are complete. A server that published one artifact per release and dropped the rest would validate just as cleanly. This section reports what the published graph actually contains.

MeasureValue
Products sampled300
Releases sampled24
Collections read24
Collections with no artifacts3
Artifacts published28
Artifacts per collection (mean)1.2
Artifacts carrying a checksum0
Artifacts carrying a media type28
Artifacts carrying a download URL28
Artifacts with more than one revision0
Deepest artifact revision1
Deepest collection version2
Releases flagged pre-release7
Releases flagged final93

Published artifact types

artifact-typeCount
ATTESTATION9
RELEASE_NOTES19

Published documents

DocumentCount
OpenSSF Scorecard9
Release Notes19

Artifact revision depth

How many immutable revisions each published artifact has. Depth beyond 1 is TEA’s (uuid, version) identity doing real work.

RevisionsArtifacts
128

Coverage by operation

OperationMethodPathCasesPassSchema OKp50p95maxVerdict
discoveryByTeiGET/discovery664/441.70 ms61.07 ms61.07 msPASS
getArtifactByVersionGET/artifact/{uuid}/{artifactVersion}442/261.13 ms61.46 ms61.46 msPASS
getCleByComponentIdGET/component/{uuid}/cle332/235.65 ms35.80 ms35.80 msPASS
getCleByComponentReleaseIdGET/componentRelease/{uuid}/cle332/246.30 ms65.01 ms65.01 msPASS
getCleByProductIdGET/product/{uuid}/cle332/2121.02 ms125.40 ms125.40 msPASS
getCleByProductReleaseIdGET/productRelease/{uuid}/cle332/2197.70 ms215.19 ms215.19 msPASS
getCollectionGET/componentRelease/{uuid}/collection/{collectionVersion}442/232.56 ms61.42 ms61.42 msPASS
getCollectionForProductReleaseGET/productRelease/{uuid}/collection/{collectionVersion}442/2126.93 ms132.48 ms132.48 msPASS
getCollectionsByProductReleaseIdGET/productRelease/{uuid}/collections13136/6139.82 ms157.50 ms158.38 msPASS
getCollectionsByReleaseIdGET/componentRelease/{uuid}/collections13136/649.22 ms88.72 ms90.96 msPASS
getComponentReleaseByIdGET/componentRelease/{uuid}332/265.91 ms65.98 ms65.98 msPASS
getLatestArtifactGET/artifact/{uuid}/latest332/261.33 ms61.66 ms61.66 msPASS
getLatestCollectionGET/componentRelease/{uuid}/collection/latest332/245.36 ms49.15 ms49.15 msPASS
getLatestCollectionForProductReleaseGET/productRelease/{uuid}/collection/latest332/2197.88 ms213.51 ms213.51 msPASS
getReleasesByComponentIdGET/component/{uuid}/releases13136/635.99 ms37.63 ms37.80 msPASS
getReleasesByProductIdGET/product/{uuid}/releases191912/1246.82 ms156.92 ms161.27 msPASS
getTeaComponentByIdGET/component/{uuid}332/223.41 ms24.01 ms24.01 msPASS
getTeaProductByUuidGET/product/{uuid}442/2103.89 ms104.01 ms104.01 msPASS
getTeaProductReleaseByUuidGET/productRelease/{uuid}332/2216.01 ms270.69 ms270.69 msPASS
queryTeaComponentReleasesGET/componentReleases11115/547.39 ms141.56 ms141.56 msPASS
queryTeaComponentsGET/components12125/524.10 ms73.00 ms113.99 msPASS
queryTeaProductReleasesGET/productReleases12126/6140.66 ms257.85 ms289.88 msPASS
queryTeaProductsGET/products14146/641.79 ms162.48 ms162.82 msPASS

Discovery document

GET https://www.vulnetix.com/.well-known/tea (unauthenticated), validated against tea-well-known.schema.json: PASS

Coverage by case category

CategoryCasesPassedFailed
conformance24240
discovery110
filtering220
negative93930
pagination38380
security220

Fixtures

The run walked the object graph from /products outwards; these are the live identifiers it resolved.

ObjectIdentifier
TEA Product78118e84-eba5-5eb8-82ea-2ba57cbf9740 (666OS/ClashMac)
TEA Product Releaseb95dc7ed-f929-58dd-8c03-3bcabc10d290 (version ClashMac-Legacy)
TEA Component077af7e9-7881-5965-89bd-015a03ae00cd
TEA Component Release1aa544fe-d842-558a-9386-98b8ecd1bbf5
TEA Artifact73a30083-6785-5c70-b8f0-6bbaaafd7cdb

Method

Every response was validated client-side against the schema the specification declares for that operation and status code, compiled directly from the vendored openapi.yaml. OpenAPI 3.1 schema objects are JSON Schema 2020-12, so there is no translation step between what the specification says and what was enforced here.

Assertions the schemas cannot express, such as collection/release UUID identity, CLE event ordering, pagination-token consistency and additionalProperties:false on error bodies, were checked separately against the normative prose, and are reported as case failures in the same way as schema violations.